Ask Muna – Privacy Policy
Last updated: 22 June 2026
This Privacy Policy explains what we collect, why, who else processes your data, and the rights you have over it. It's written to be honest and specific — not generic boilerplate.
1. Who we are
Ask Muna is operated by AMD Digital Ltd, registered in the United Kingdom (company number 15164590). For the purposes of UK GDPR we are the data controller.
- Service: a consumer wellness chat app and personal health plan tracker at https://www.askmuna.com
- Contact: hello@askmuna.com
- Jurisdiction: United Kingdom
2. The data we collect
We collect only what we need to run the service. Specifically:
Account data (everyone)
- Email address (required to sign up)
- Password hash (we never see your password in plaintext)
- OAuth identity if you sign in with Google or Facebook
- Subscription status from Stripe (whether you're Free or Premium, current plan, renewal date)
Chat data (everyone)
- The messages you send to Muna and the responses she gives
- Uploaded documents (lab PDFs, photos of supplement labels, etc.) and the text we extract from them
- A monthly count of how many messages you've sent (to enforce the free tier)
Plan and tracking data (Premium only — opt-in by signing up to Premium)
- Conditions, allergies, medications, goals, symptoms and lifestyle facts you share with Muna or add manually on
/me - Supplements you're taking (name, dose, frequency, reason, status)
- Daily check-ins: which supplements you ticked as "taken" today, which habits you completed
- Daily metrics: your 1–10 ratings for energy, sleep, mood and any other metric you've chosen to track
- Daily journal: free-text notes about how you felt
- Test results: any biomarker values you've entered manually or that Muna has extracted from a lab document
- Data you import: anything you paste into the tracker-import tool (Cronometer, Oura, Garmin, CGM exports, etc.) — parsed and stored in the same format as your manual entries
Technical data (everyone)
- IP address, browser type, device type, approximate location (city level)
- Pages you visit, buttons you click — only if you have accepted analytics cookies. Without consent, we do not collect this.
- Error logs if something breaks
Push notification data (only if you opt in)
- If you enable daily reminders, we store the browser-issued push endpoint URL plus the cryptographic keys your browser generates so we can deliver the reminder. No content — just enough to address a push to your device. You can turn this off any time from
/account→ Notifications.
Payment data (Premium only)
- Handled entirely by Stripe. We see your email, plan, status and renewal date. We never see or store your card number.
3. How we use your data
- To run the service: authenticate you, deliver Muna's responses, remember your plan across sessions if you're Premium.
- To process payments: pass billing to Stripe, sync subscription status.
- To improve the service: aggregate, anonymised usage patterns (if you've accepted analytics cookies). We never sell or share individual usage data.
- To send service emails: account confirmation, password reset, billing receipts. We don't send marketing emails without a separate opt-in.
- To enforce abuse limits: monthly message counts for the free tier; rate limiting to stop scripted abuse.
We do not use your data to train AI models. Where our AI providers' commercial terms allow training on customer inputs, we have opted out wherever the option is offered. We have no internal AI training pipeline and never will.
4. Sub-processors (who else touches your data)
We use the following service providers. Each one is bound by a data processing agreement and only sees data necessary for their specific function.
| Provider | What they do | Where data is stored | Data they see |
|---|---|---|---|
| Supabase | Database, authentication, file storage, edge functions | EU (eu-west-2, London) | Everything in your account |
| Vercel | Web app hosting (frontend) | Global edge | IP, browser type, requested pages |
| Anthropic | Claude AI (Premium chat, document extraction) | US | The messages you send to Muna, uploaded document text |
| Gemini AI (free-tier chat, tracker import parsing) | US | The messages you send to Muna, tracker data you paste | |
| OpenAI | Text embeddings for the knowledge base only | US | Only knowledge-base content — never your chats |
| Stripe | Payment processing and subscription management | US / EU | Email, plan, billing address, card details (we do not see the card) |
| Resend | Transactional emails (signup confirm, password reset, billing) | EU | Email address, message contents |
| PostHog | Product analytics, only if you accept analytics cookies | EU (eu.i.posthog.com) | Pages visited, buttons clicked, user id (no chat content, no health data) |
For international transfers to the US (Anthropic, Google, OpenAI, Stripe), we rely on the European Commission's adequacy decisions (Data Privacy Framework) and Standard Contractual Clauses where applicable.
5. Cookies
We use the minimum cookies necessary:
- Essential cookies: keep you logged in, remember your cookie consent choice. Always on — required for the site to work.
- Analytics cookies (PostHog): only if you click "Accept all" on the cookie banner. You can change your choice at any time via the Cookie preferences link in the footer.
We don't use advertising or marketing cookies.
6. How long we keep your data
- Account data: kept while your account is active. Deleted within 30 days of you closing the account.
- Chat history (Premium memory): kept while your account is active so Muna can reference past conversations. You can delete individual chats or your entire history from your account.
- Documents you upload: kept until you delete them or close your account.
- Subscription data from Stripe: retained for 7 years after your last invoice for tax / accounting compliance (UK statutory requirement).
- Analytics events: 12 months, then aggregated.
- Logs: 30 days for technical logs, 90 days for security logs.
7. Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you
- Correct anything that's wrong
- Delete your data (request deletion at
/data-deletion— fully self-serve, takes effect within 30 days) - Restrict or object to specific types of processing
- Portability — get your data in a machine-readable format
- Withdraw consent for analytics at any time (toggle via Cookie preferences)
- Complain to the UK Information Commissioner's Office: https://ico.org.uk
To exercise any right, email hello@askmuna.com. We'll respond within 30 days.
8. Children
AskMuna is not for under-18s. We don't knowingly collect data from anyone under 18. If you believe a child has signed up, contact hello@askmuna.com and we'll delete the account.
9. Security
- All data encrypted in transit (TLS 1.2+)
- All data encrypted at rest (our sub-processors use industry-standard AES-256 or equivalent)
- Passwords are securely hashed before storage — we never see or store the plaintext
- You can sign in with Google or Facebook for stronger account security
- We never email you your password or ask you for one
No system is 100% secure. If a breach affecting your data ever happens, we'll notify you and the ICO within 72 hours as required by law.
10. AskMuna is not medical advice
Nothing on AskMuna is a substitute for medical care. For anything acute, life-threatening, or specialist-managed, see your GP or A&E. See /faq for When not to use AskMuna.
11. Changes to this policy
We'll update this page when anything material changes (new sub-processor, new data type collected, etc.) and update the "Last updated" date at the top. Material changes will also be flagged via in-app banner or email.
12. Contact
Email: hello@askmuna.com
Postal: AMD Digital Ltd, United Kingdom (company number 15164590)
If you want to talk to someone about a privacy concern specifically, email with "Privacy" in the subject — we'll route it appropriately.